Overview
ISO/IEC 23751:2022 - Information technology - Cloud computing and distributed platforms - Data sharing agreement (DSA) framework - defines a common set of building blocks (concepts, terms and definitions) to create consistent Data Sharing Agreements (DSAs) for data processed on cloud services and other distributed platforms. The standard introduces the twin concepts of Data Level Objectives (DLOs) and Data Qualitative Objectives (DQOs) to describe and govern dataset characteristics and expected behaviors across the data lifecycle. Its purpose is to reduce time and cost in initiating data sharing projects by providing standardized terminology and modular agreement elements.
Key topics and technical requirements
- DSA structure and roles: Guidance on DSA purpose, parties (data originator, data holder, data user), trust relationships, and data flow elements.
- Dataset description: Standardized metadata elements (title, domain, data dictionary, format, data types, gathering policy, revision history, statistics) to enable interoperable dataset identification and assessment.
- DLOs and DQOs: Mechanisms for specifying measurable objectives and qualitative controls for datasets (used to express requirements for quality, provenance, integrity, access and use).
- Data use obligations and controls: Templates for allowed/disallowed uses, regulatory controls, holder/user obligations, and permitted uses of processing outputs.
- Provenance, quality and integrity: Requirements for data provenance records, quality metrics and integrity controls to support trustworthiness and reproducibility.
- Chain of custody and transfer of custody: Elements to record custody paths and handover requirements for accountability across distributed platforms.
- Security and privacy: Security and privacy objectives for both data holders and data users when processing on cloud or distributed platforms.
- Proof of compliance: Methods and mechanisms for demonstrating conformance with DLOs/DQOs and DSA requirements.
- Governance and ecosystem considerations: Informative guidance on governance models and alternatives to bespoke DSAs.
Applications and practical value
- Accelerates negotiation and drafting of DSAs for cloud migration, cross-organization analytics, AI model training, IoT data sharing, and research consortia.
- Improves interoperability and clarity between data providers, cloud service providers, platform operators, and data consumers.
- Supports regulatory compliance efforts by documenting data use limits, provenance, custody and proof of compliance.
- Helps reduce legal and operational risks when combining datasets for Big Data, machine learning, or multi-party data ecosystems.
Who should use this standard
- Legal and compliance teams drafting DSAs
- Data stewards and data governance leads
- Cloud architects and platform operators
- Security and privacy officers
- Researchers and consortium leads managing shared datasets
Related standards
- Annex C references complementary ISO/IEC standards for identity, privacy, chain of custody, forensics and security, which organizations should consult when implementing DSAs under ISO/IEC 23751:2022.